sailpoint-toxic-access-detector

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The SailPoint Toxic Access Detector skill appears coherently aligned with its stated purpose: it uses SailPoint ISC APIs to fetch SoD policies, violations, and identities, analyzes access patterns, and generates a risk-focused report. There are no evident download-execute patterns or unverifiable binaries, reducing supply-chain concerns. The primary risk points concern data privacy (exposure of identity/entitlement data in reports) and potential data exfiltration through report sharing or logging. Overall, the footprint is proportionate to the task, though security-conscious handling of sensitive data and access control for report generation should be explicitly specified in the documentation to elevate safety posture.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 11:29 AM
Package URL
pkg:socket/skills-sh/AnasSahel%2Fsupersail%2Fsailpoint-toxic-access-detector%2F@cd7f9c27057a320525636cf33609afa09ce56fc3